← Back to browse · API

CVE-2018-17480

Severity
HIGH
CVSS
8.8
EPSS
0.3564
Risk score
72.67
CISA KEV
Yes
PoC
No
Published
2018-12-11
Modified
2025-10-21
First seen
2026-08-07
Aliases
EUVD-2018-9233, GHSA-RFP6-W338-JP8M
Products
Google:Chrome unspecified <71.0.3578.80, Google:Chromium V8
Sources
cisa.gov CVE-2018-17480
euvd EUVD-2018-9233

Description

Execution of user supplied Javascript during array deserialization leading to an out of bounds write in V8 in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.

References